Microsoft runs Microsoft 365. Protecting the data inside it is your job, not theirs. Here is the evidence, the risk and what a defensible backup strategy looks like for a South African organisation in 2026.
By the Nymbis Product Team · 29 July 2026 · 8-minute read
The short answer
No, Microsoft does not back up your Microsoft 365 data in the way most people assume. Microsoft keeps the service running and resilient. Recovering your content after deletion, corruption, ransomware or a retention gap is your responsibility. This is not a loophole or an oversight. It is written into how the service works, in plain terms that Microsoft states itself.
For a South African organisation, that responsibility comes with a local edge: the Protection of Personal Information Act (POPIA) expects you to prevent the loss and destruction of personal information and it regulates where that data can go. This article lays out the evidence for all of it and what a sensible backup strategy looks like.
What “shared responsibility” actually means
Every major cloud platform runs on a shared responsibility model. The provider secures and operates the infrastructure. The customer owns and protects their own data and identities. Microsoft’s own documentation is explicit: across every cloud deployment type, including software-as-a-service, “you own your data and identities” and customer data is listed as the customer’s responsibility.
Microsoft’s Services Agreement goes further. In its section on service availability, it states: “We recommend that you regularly backup Your Content and Data that you store on the Services.” It also warns that in the event of an outage “you may not be able to retrieve Your Content or Data” and that Microsoft “is not liable for any disruption or loss you may suffer as a result.”
Read those two documents together and the picture is clear. Microsoft provides platform-level resilience: your service stays up and data is replicated across its datacentres for availability. What it does not provide is a long-term, independent backup that lets you roll back a deletion, recover from ransomware or reinstate a departed employee’s mailbox months later. That is the gap a dedicated backup fills.
Why replication is not backup
A common objection is: “But my data is already in the cloud, in multiple copies. Is that not a backup?” It is not. The distinction matters.
Replication keeps identical copies of your data in sync for availability. That is a strength for uptime and a weakness for recovery because the bad changes replicate too. Delete a mailbox and the deletion propagates. Encrypt a SharePoint site with ransomware and the encrypted version syncs across the service. A second live copy of corrupted data is still corrupted data.
A true backup is different in three ways: it is independent of the live tenant, it is point-in-time so you can go back to before the damage and it is retained on your terms rather than the platform’s default window. Those three properties are exactly what native retention does not guarantee.
The seven ways Microsoft 365 data actually gets lost
Data loss in Microsoft 365 is rarely dramatic. It is usually mundane and it comes from seven recurring directions:
- Accidental deletion. The single most common cause. A file, a folder or an entire mailbox removed by mistake, discovered long after the recycle bin has emptied.
- Internal threats. A disgruntled employee, or simple human error with elevated permissions.
- External threats. Attackers who reach your tenant through phishing or compromised credentials.
- Ransomware. Encryption that spreads through synced files and shared sites.
- Retention-policy gaps. The classic example: a leaver’s account is removed to reclaim a licence and native retention permanently deletes that data after its window closes.
- Legal and compliance holds. The obligation to preserve and produce data long after users would otherwise have deleted it.
- Hybrid management. Complexity across on-premises and cloud that hides where the gaps are.
Native Microsoft 365 tools address some of these partly and none of them completely. That is not a criticism of Microsoft. It is simply the customer’s side of the shared responsibility line.
The evidence: this is now a mainstream expectation, not a fringe worry
Backing up software-as-a-service data has moved from best practice to baseline expectation and the analyst data shows the shift clearly.
Gartner predicts that by 2028, 75% of enterprises will prioritise backup of SaaS applications as a critical requirement, up from just 15% in 2024. That is a 5X jump in four years and it tells you where the market consensus is heading.
Veeam’s 2024 Data Protection Trends Report, a survey of 1,200 IT leaders, found that 88% of organisations already use or expect to use backup-as-a-service within two years. Adoption of third-party SaaS backup is close to universal.
The threat side is just as stark. Microsoft reports that its customers face more than 600 million attacks every day and that it blocks around 7,000 password attacks every second. Ransomware and extortion drive a large share of attacks with a known motive.
The scale of protection tells the same story from the other direction. More than 25 million Microsoft 365 users are now protected by Veeam, the number one data-protection platform by market share and a Gartner Magic Quadrant Leader for ten consecutive years. When a category grows to 25 million protected users, it is no longer a niche precaution.
Why this hits differently in South Africa
The global case for Microsoft 365 backup is strong. The South African case is sharper still, for two reasons: the local threat level and POPIA.
On threat: INTERPOL’s 2025 Africa Cyberthreat Assessment identifies South Africa as the most ransomware-affected country on the continent. Sophos found that 60% of ransomware attacks on South African organisations in 2025 encrypted data, higher than the global average, with average recovery costs running into the millions of rand. IBM’s 2025 report put the average South African data-breach cost at R44.1 million. Whatever your view on probability, the impact is now a board-level number.
On compliance, precision matters, because this is where marketing often overreaches. POPIA does not require you to keep data inside South Africa. There is no data-localisation mandate in the Act. What POPIA does do is two things that bear directly on backup.
First, Section 19 requires a responsible party to secure the integrity and confidentiality of personal information and to guard against its loss, damage or unlawful destruction, using generally accepted information security practices. Keeping a recoverable backup is squarely within that duty.
Second, Section 72 regulates the transfer of personal information outside South Africa. You may only transfer it abroad under specific conditions, such as the recipient being subject to adequate protection. The Information Regulator has not yet published an adequacy framework or a list of approved countries, so offshore backup carries genuine assessment work and regulatory uncertainty.
The practical conclusion is straightforward. In-country backup is not a POPIA requirement, but it is the simplest, lowest-risk way to stay on the right side of it. Keep your Microsoft 365 backup in South Africa and the Section 72 cross-border transfer conditions never apply, while the Section 19 duty to keep data recoverable is met. That is a defensible position and it is a stronger one than claiming a mandate that does not exist.
What a defensible Microsoft 365 backup strategy looks like
If you are building or reviewing a strategy, five principles hold up:
- Independent of the tenant. The backup must live outside the live Microsoft 365 environment, so that whatever happens to the tenant does not happen to your backup.
- Comprehensive across workloads. Exchange, SharePoint, OneDrive and Teams at minimum, with Entra ID identity backup where governance demands it. Identities are attacked constantly and are painful to rebuild by hand.
- Point-in-time and granular. Recover a single item or a full tenant, from a chosen moment before the damage.
- Retained on your terms. Retention set to your policy and your compliance needs, not the platform’s default deletion window.
- Recoverable at speed, in-country. Fast restore without throttling, from storage held in South Africa, so recovery is both quick and compliant.
These are not exotic requirements. They are the baseline that the analyst forecasts, the threat data and POPIA together now imply.
Where Nymbis fits
Nymbis Backup for Microsoft 365 is built on Veeam Data Cloud and delivered by a Veeam Platinum Partner, with all five principles above built in. Your data flows securely from Microsoft into in-country storage, with unlimited storage included and granular recovery from a single item to a full tenant.
The portfolio runs from Foundation at R54.04 per user a month for core backup, through Advanced at R64.84 for identity and compliance, Express at R86.46 for enterprise disaster recovery, to Premium at R118.88 for the full stack. Entra ID identity backup can be added to any base plan for R15.13 per user a month. Pricing is in rand, so there is no exchange-rate surprise and Nymbis handles setup, support and escalation directly.
The point is not the price list. It is that the responsibility for your Microsoft 365 data is already yours. The only question is whether you have accepted it deliberately, with a backup you have tested, or by default, only to find out the hard way.
Frequently Asked Questions
Does Microsoft back up Microsoft 365 data?
No, not in the sense of a recoverable, long-term, independent backup. Microsoft keeps the service available and resilient; its own Services Agreement recommends that customers regularly back up their content. Under the shared responsibility model, protecting and recovering your data is the customer’s job.
Is the Microsoft 365 recycle bin or retention policy enough?
Not on its own. Recycle bins and native retention have time limits and gaps. Once the window closes, for example after a leaver’s account is removed, that data can be permanently deleted. Native retention also does not protect against ransomware that syncs across the service.
Does POPIA require Microsoft 365 backups to be stored in South Africa?
No. POPIA does not mandate data localisation. It does require you to prevent the loss or destruction of personal information (Section 19) and it regulates cross-border transfers (Section 72). Keeping backups in South Africa is the simplest way to avoid the Section 72 conditions, but it is a prudent choice rather than a legal requirement.
What should a Microsoft 365 backup actually cover?
At minimum Exchange, SharePoint, OneDrive and Teams, with Entra ID identity backup where governance requires it. It should be independent of the live tenant, point-in-time, granular, retained on your terms and recoverable at speed.
How much does Microsoft 365 backup cost in South Africa?
Nymbis Backup for Microsoft 365 on Veeam Data Cloud starts at R54.04 per user a month for the Foundation plan, rising to R118.88 for Premium full-stack protection, with an Entra ID add-on at R15.13 per user a month. All plans include unlimited storage and in-country data.